Description
A stored cross-site scripting (XSS) vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user can exploit it by injecting malicious Javascript into the name of main website.
Remediation
References
Related Vulnerabilities
WordPress Plugin Facebook Page Feed Timeline Cross-Site Scripting (1.0)
WordPress Improper Access Control Vulnerability (CVE-2015-5623)
MediaWiki Improper Encoding or Escaping of Output Vulnerability (CVE-2020-35475)
Drupal Core 8.x Security Bypass (8.0.0 - 8.5.5)
WordPress Plugin Easy Forms for Mailchimp PHP Code Injection (6.5.2)